5.5

CVSS3.1

CVE-2024-47661 - drm/amd/display: Avoid overflow from uint32_t to uint8_t

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid overflow from uint32_t to uint8_t [WHAT & HOW] dmub_rb_cmd's ramping_boundary has size of uint8_t and it is assigned 0xFFFF. Fix it by changing it to uint8_t with value of 0xFF. This fixes 2 INTEGER_OVERFL…

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: July 11, 2025, 5:20 p.m.

5.4

CVSS3.1

CVE-2024-25282 -

DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: Oct. 22, 2024, 9:15 p.m.

9.8

CVSS3.1

CVE-2024-25825 -

FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-46307 -

A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: Oct. 15, 2024, 2:57 p.m.

7.8

CVSS3.1

CVE-2024-35288 -

Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a conhost.exe window, and there is a mechanism allowing CTRL+o to launch cmd.exe as NT AUTHORITY\SYSTEM.

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-25283 -

DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: Oct. 22, 2024, 9:15 p.m.

5.5

CVSS3.1

CVE-2024-47666 - scsi: pm80xx: Set phy->enable_completion only when we wait for it

In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Set phy->enable_completion only when we wait for it pm8001_phy_control() populates the enable_completion pointer with a stack address, sends a PHY_LINK_RESET / PHY_HARD_RESET, waits 300 ms, and returns. The problem …

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:53 a.m.

9.8

CVSS3.1

CVE-2024-45746 -

An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a pointer to a list of input arguments (in_vec) and output arguments (out_vec). These list pointers are never validated. Each argument list contains a buffer pointer and a buffer len…

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-48941 -

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted.

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: Oct. 11, 2024, 9:36 p.m.

7.2

CVSS3.1

CVE-2024-45179 -

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validation, the C-MOR web interface is vulnerable to OS command injection attacks. It was found out that different functionality is vulnerable to OS command injection attacks, for example …

πŸ“… Published: Oct. 9, 2024, midnight πŸ”„ Last Modified: Sept. 4, 2025, 4:34 p.m.
Total resulsts: 349182
Page 8347 of 34,919
Β« previous page Β» next page
Filters